Firewall Engineer (Palo Alto) Tech Refresh & Support
Ft Meade, MD
Full Time
Experienced
Job Description: Firewall Engineer (Palo Alto) — Tech Refresh & Support -(OSS) Legacy Systems Sustainment
This position supports the Defense Information Systems Agency (DISA) Transport Services Directorate (IE) and its Cyber NetOps Tools Division (IEA) on the Operational Support System (OSS) Legacy Systems Sustainment effort. OSS comprises tools and enclaves used by DISA Tier II/III to monitor, control, analyze, and manage DoDIN/DISN equipment; while OSS is a legacy environment being replaced by the cloud‑based Global Management System (GMS), it must be sustained to ensure continuity of operations during transition. Primary work is performed at Ft. Meade.
Mission of the role. Your charge is to keep OSS reliable, secure, and accredited across lab and production by sustaining: (1) the OSS Lab Network, (2) Network Services (AAA, DNS, NTP, Syslog, SAN/NAS/Brocade, RDP), (3) CDBA, (4) JSME, and (5) OSS Firewalls/technical refresh—using a lab‑first pipeline, disciplined change control (IP/DP with reversion), STIG/IAVA patching, and clear documentation.
Overview:
The Firewall Engineer leads technical refresh and sustainment for OSS firewalls—qualifying replacements for PA‑3020/3220/5050, producing device configuration/implementation guides, and supporting model‑by‑model rollouts.
Support Scope:
Qualify devices; patch/STIG/DTO compliance; ACAS scan support; lab‑first testing; implement IPv6/SNMPv3 transitions; provide break‑fix support and documentation (device configs, connectivity diagrams, IP/DPs, test reports, RFCs).
Key Responsibilities:
Qualification & Deployment
PD INC is an Equal Opportunity Employer.
This position supports the Defense Information Systems Agency (DISA) Transport Services Directorate (IE) and its Cyber NetOps Tools Division (IEA) on the Operational Support System (OSS) Legacy Systems Sustainment effort. OSS comprises tools and enclaves used by DISA Tier II/III to monitor, control, analyze, and manage DoDIN/DISN equipment; while OSS is a legacy environment being replaced by the cloud‑based Global Management System (GMS), it must be sustained to ensure continuity of operations during transition. Primary work is performed at Ft. Meade.
Mission of the role. Your charge is to keep OSS reliable, secure, and accredited across lab and production by sustaining: (1) the OSS Lab Network, (2) Network Services (AAA, DNS, NTP, Syslog, SAN/NAS/Brocade, RDP), (3) CDBA, (4) JSME, and (5) OSS Firewalls/technical refresh—using a lab‑first pipeline, disciplined change control (IP/DP with reversion), STIG/IAVA patching, and clear documentation.
Overview:
The Firewall Engineer leads technical refresh and sustainment for OSS firewalls—qualifying replacements for PA‑3020/3220/5050, producing device configuration/implementation guides, and supporting model‑by‑model rollouts.
Support Scope:
Qualify devices; patch/STIG/DTO compliance; ACAS scan support; lab‑first testing; implement IPv6/SNMPv3 transitions; provide break‑fix support and documentation (device configs, connectivity diagrams, IP/DPs, test reports, RFCs).
Key Responsibilities:
Qualification & Deployment
- Build golden configs; validate in lab; release by device model/site; author connectivity diagrams.
Operations & Break‑Fix - Restore traffic during outages; coordinate high‑risk changes; recommend replacements for EoL/EoS gear.
Security Compliance - Maintain STIG/IAVA posture; support accreditation data calls.
- 5+ years enterprise firewall administration; Palo Alto NGFW experience.
- DoD 8140 IAT‑II; strong with routing, HA, content updates, and rule hygiene.
- PCNSE, PCCET/PCNSA; Security+ or CASP+.
- On‑site for lab/prod coordination; some work on high side. Clearance: Top Secret/Secret; NIPR/SIPR; OSS enclaves.
PD INC is an Equal Opportunity Employer.
Apply for this position
Required*